#VU20477 Information disclosure in Discourse - CVE-2019-15515
Published: August 30, 2019 / Updated: January 29, 2020
Discourse
Civilized Discourse Construction Kit, Inc.
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to software sends CSRF token in the query string. A remote attacker can gain access to the token via HTTP Referer header, bypass implemented CSRF protection mechanisms and perform CSRF attack